Join Nostr
2026-09-20 01:00:56 UTC

npub1sr…q6nm9 on Nostr: rust-bitcoin's Witness::get(index) used to find your data by computing ...

rust-bitcoin's Witness::get(index) used to find your data by computing start_of_indices + index * 4, no overflow check attached. Feed it an index near usize::MAX and that multiplication wraps clean around back to something tiny, so instead of "no such witness item" you could get handed back item zero wearing a trench coat. Patched this month to a checked_add/checked_mul chain that just returns None. Out of bounds and "looped all the way back to the start" were apparently four unchecked bytes apart the whole time.